Privacy Policy
Last updated: August 26, 2026
Effective date: August 26, 2026
RidgePoint Risk Advisory ("RidgePoint," "we," "us," or "our"), operated by Gillespie Technologies Inc., doing business as RidgePoint Risk Advisory, provides a vendor-risk management platform and related advisory services (the "Services") at ridgepointrisk.com (the "Site"). This Privacy Policy explains how we collect, use, disclose, and safeguard information.
By using the Site or Services, you agree to this Privacy Policy.
1. Scope
This policy covers:
- Site visitors and leads who submit our contact and lead forms.
- Customer users (employees of our business customers) who use the portal.
- Vendor respondents who complete tokenized assessment pages.
This policy does not govern how our customers handle data within their own organizations. When we process data on a customer's behalf, we act as a service provider / processor under that customer's instructions and our Data Processing Agreement.
2. Information we collect
You provide directly:
- Contact details (name, business email, company, phone) via lead and invite forms.
- Account credentials and profile information.
- Assessment content, responses, and uploaded evidence files.
- Communications you send us.
Collected automatically:
- Device, browser, IP address, and usage data via server logs.
- Authentication and session data.
From third parties:
- Limited data from our infrastructure and email providers. See the subprocessor list in our Security Overview.
We do not intentionally collect special categories of data (health, biometric, and similar) or data from children under 16.
3. How we use information
- Provide, operate, secure, and improve the Services.
- Authenticate users and manage access (Supabase Auth with Row Level Security).
- Send transactional and invite emails.
- Respond to leads and support requests.
- Comply with legal obligations and enforce our Terms.
Legal bases (US): performance of a contract, our legitimate business interests, consent where required, and compliance with law.
4. How we share information
We share information only with:
- Subprocessors that power the Services (hosting, database, email, business email). See the current list in our Security Overview.
- Our business customer whose account the data belongs to.
- Professional advisors or authorities where required by law.
- A successor in a merger, acquisition, or asset sale.
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
5. Cookies
We use strictly necessary cookies only — those required for authentication, session management, and security. We do not use third-party advertising cookies, cross-site tracking, or behavioral analytics on the Site. You can control cookies through your browser, though disabling strictly necessary cookies will prevent you from signing in.
6. Data retention
We retain information for as long as needed to provide the Services, then according to our retention schedule and legal obligations. Customer data is deleted or returned per the Data Processing Agreement upon account termination, within 30 days of termination unless a longer period is required by law.
7. Security
We use Supabase (Postgres with Row Level Security), private Storage with short-lived signed URLs, tokenized vendor links (only hashes are stored server-side), encryption in transit and at rest, and least-privilege access. See our Security Overview for detail. No system is perfectly secure, and we cannot guarantee absolute security.
8. Your privacy rights
Depending on your US state of residence (for example California, Virginia, Colorado, Connecticut, and Utah), you may have rights to:
- Know or access the personal information we hold.
- Correct or delete it.
- Opt out of sale or sharing. We do neither.
- Non-discrimination for exercising these rights.
To exercise these rights, contact privacy@ridgepointrisk.com. We will verify your identity before responding. If you are a customer user or vendor respondent, direct requests to the customer that controls your data; we will assist them in responding.
9. International users
The Services are operated in the United States and intended for US users and businesses. If you access them from outside the US, you consent to processing in the US.
10. Changes
We may update this policy. Material changes will be posted here with a new "Last updated" date and, where appropriate, notified by email.
11. Contact
Gillespie Technologies Inc., doing business as RidgePoint Risk Advisory
81 Fern Hill Drive, Granville, OH 43023
Email: privacy@ridgepointrisk.com